Privacy Policy
This Privacy Policy explains what personal data HukProof collects, why and how we process it, who we share it with, how long we keep it, how we protect it, and the rights you have under the EU/UK General Data Protection Regulation (“GDPR”), India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), and the California Consumer Privacy Act as amended by the CPRA (“CCPA”). Please read it together with our Terms of Service, Acceptable Use Policy, and Cookie Policy.
1. Scope
This policy applies to our websites, the HukProof application, and related services (the “Service”). It does not apply to third-party websites or services we link to but do not operate. If you are an employee whose data was uploaded by an employer using HukProof, please also see section 2 — your employer, not HukProof, is primarily responsible for that data.
2. Who we are & our two roles
HukProof (“HukProof”, “we”, “us”, “our”) provides a security-awareness and phishing-simulation platform, and is the controller of the account data described below. You can reach us at privacy@hukproof.com; our postal address is available on request. We process personal data in two distinct capacities:
- As a controller / data fiduciary — for the account data of the administrators who sign up for and operate the Service. We determine how that data is used, and this policy governs it directly.
- As a processor / data processor — for the workforce data a customer uploads about their own employees (the simulation recipients). Our customer is the controller/fiduciary of that data; we process it only on their documented instructions to provide the Service. If you are such an employee, direct rights requests to your employer first; we will assist them in responding.
3. Definitions
- Personal data — any information relating to an identified or identifiable individual.
- Processing — any operation performed on personal data (collection, storage, use, disclosure, deletion, etc.).
- Controller / Data Fiduciary — the party that determines the purposes and means of processing.
- Processor — a party that processes personal data on behalf of a controller.
- Sub-processor — a third party we engage to help process personal data (see our Sub-processors page).
4. Data we collect
4.1 Account & organization data (we are the controller)
- Identity & login — name, work email, hashed password, and two-factor (TOTP) secrets. Passwords are never stored in plaintext.
- Security telemetry — sign-in timestamps, IP address, and coarse geolocation (city/region/country derived from IP), used to secure your account and detect abuse.
- Organization profile — company name, your registered email domain, plan tier, and onboarding questionnaire answers.
- Support & communications — messages you send us and our responses.
- Billing — if and when paid plans launch, payment data is handled by our payment processor; we do not store full card numbers.
4.2 Workforce / recipient data (we are the processor)
- Employee records a customer imports — names and email addresses, optional department and timezone. Names and email addresses are encrypted at rest with AES-256-GCM under a per-organization key; only the email domain is stored in the clear (to enforce our domain-restriction safeguard).
- Simulation results — whether a simulated message was delivered, opened, its link clicked, or its QR code scanned, and derived risk scores. We never capture passwords or credentials. If a simulation includes a mock sign-in page, we record only which fields were submitted and their lengths — never the values typed.
- QR-code (“quishing”) simulations. A simulated message may carry a QR code. For a shared QR (used for a whole team or a poster), there is no per-person link, so if a recipient types an email address on the mock sign-in page, that address is matched in memory against the employer’s own employee list solely to attribute the result to a known employee; the typed address itself is not stored, and non-matching addresses are discarded (only an anonymous count remains).
4.3 Automatically-collected data
We collect limited technical data (IP, device/browser type, and log data) to operate and secure the Service. See our Cookie Policy — we use only a strictly-necessary session cookie and no advertising or cross-site tracking cookies.
5. How & why we use data, and our legal bases
We process personal data to provide, maintain, secure, and improve the Service; to communicate with you; to prevent abuse and enforce our policies; and to comply with law. Our legal bases, depending on the law that applies, are:
- Performance of a contract (GDPR Art. 6(1)(b)) — to deliver the Service you signed up for.
- Consent — the primary lawful basis under the DPDP Act, and used under the GDPR where required (you may withdraw it at any time without affecting prior processing).
- Legitimate interests (GDPR Art. 6(1)(f)) — to keep our platform and your account secure and to prevent misuse; we balance these against your rights. (The DPDP Act does not recognize legitimate interest; in India we rely on consent or a legally-permitted use.)
- Legal obligation — to comply with applicable law and lawful requests.
We do not sell personal data, and we do not “share” it for cross-context behavioral advertising, as those terms are defined by the CCPA.
6. Who we share data with
We share personal data only with:
- Sub-processors that help us run the Service (hosting, email delivery, and storage), each under a contract requiring appropriate safeguards. See our Sub-processors & Security page.
- Professional advisers and authorities where required by law, to establish or defend legal claims, or to protect the rights, safety, and security of our users, the public, or HukProof.
- A successor in connection with a merger, acquisition, or asset sale, subject to this policy.
7. International transfers & data residency
We may process data outside your country, including in the United States and other regions where our sub-processors operate. Where we transfer personal data internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. For customers subject to the DPDP Act, we honor applicable cross-border transfer restrictions and can discuss India data-residency options for enterprise engagements.
8. Retention
| Data | Retention |
|---|---|
| Account & organization data | For the life of the account, then deleted or anonymized (subject to legal-hold and short backup rotation). |
| Workforce / recipient data | On the customer’s instructions; deleted when the customer deletes it or closes the account. |
| Security & audit logs | A limited period as needed for security, dispute resolution, and legal compliance. |
9. Security
We protect data with encryption in transit (TLS) and at rest (AES-256-GCM with per-tenant keys for the most sensitive fields), strict tenant isolation enforced at the database layer (row-level security), optional multi-factor authentication and login lockout, least-privilege access, and audit logging. More detail is on our Security page. No method of transmission or storage is 100% secure, but we work hard to protect your data.
10. Data breach notification
If we become aware of a personal-data breach, we will act without undue delay to investigate and contain it. Where we act as a processor, we will notify the affected customer (controller) without undue delay so they can meet their obligations. Where we are the controller and the breach is likely to result in a risk to individuals, we will notify the competent supervisory authority and, where required, affected individuals in accordance with applicable law (for example, GDPR Articles 33–34 and the DPDP Act’s breach-notification requirements).
11. Automated processing & risk scoring
HukProof computes derived “risk scores” for recipients from simulation outcomes (for example, whether a link was clicked). These are indicators to help organizations target training. We do not use them to make decisions that produce legal or similarly significant effects about you by solely automated means, and any consequential decisions your employer makes should involve meaningful human review. If you are subject to solely-automated decision-making, applicable law (e.g. GDPR Art. 22) may give you the right to obtain human intervention, express your view, and contest the decision — contact your employer or us.
12. Your rights
Subject to the law that applies to you, you may have the right to:
- GDPR (EU/UK): access; rectification; erasure; restriction; objection; data portability; withdraw consent; and lodge a complaint with your supervisory authority.
- DPDP Act (India): access a summary of your data; correction, completion, updating, and erasure; grievance redressal; and the right to nominate another individual to exercise your rights. We aim to respond within statutory timeframes.
- CCPA/CPRA (California): know/access; correct; delete; opt out of any “sale”/“sharing” (we do neither); and limit use of sensitive personal information — free from discrimination for exercising your rights.
To exercise a right, email privacy@hukproof.com. We will verify your identity before acting and respond within the time required by law. You may use an authorized agent where the law permits. If your data was uploaded by an employer, we will refer your request to that customer as the controller. If we decline a request, you may appeal by replying to our response, and you may complain to your data-protection authority.
Several of these you can action yourself, immediately: from Settings → Organisation a customer administrator can download a complete copy of the organisation’s data at any time (access and portability), and permanently delete the organisation and all of its data (erasure / closing the account). Individual employee records can be corrected or removed from the Targets page. For anything else — or if you’d prefer we handle it — use the contact above.
California residents — categories & disclosures (CCPA/CPRA)
In the 12 months before this policy’s date, we collect the following categories of personal information for the business purposes described above. We do not sell personal information and do not “share” it for cross-context behavioral advertising, and we do not knowingly do so for anyone under 16.
| Category (Cal. Civ. Code § 1798.140) | Collected | Source | Disclosed to |
|---|---|---|---|
| Identifiers (name, email, IP) | Yes | You; your employer; automatically | Sub-processors |
| Customer records / contact info | Yes | You; your employer | Sub-processors |
| Commercial information (plan, billing) | Yes | You; payment processor | Sub-processors |
| Internet/network activity (usage, simulation results) | Yes | Automatically | Sub-processors |
| Geolocation (coarse, from IP) | Yes | Automatically | Sub-processors |
| Sensitive personal information | No (not intentionally collected) | — | — |
California residents may exercise the access, deletion, correction, and opt-out rights listed above at privacy@hukproof.com, without discrimination for doing so. Because we do not sell or share personal information, no “Do Not Sell or Share My Personal Information” action is required.
13. Children
HukProof is a workplace tool and is not directed to individuals under 18. We do not knowingly collect data from children; if you believe we have, contact us and we will delete it.
14. Third-party links
Our sites may link to third-party sites we do not control. Their privacy practices are governed by their own policies; we are not responsible for them.
15. “Do Not Track” & Global Privacy Control
Because we do not track users across third-party sites or serve targeted advertising, browser “Do Not Track” and Global Privacy Control signals have no additional effect — there is no cross-site tracking to disable.
16. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new “last updated” date and, where required, notified to you; we may also ask you to re-accept our policies before continuing to use the Service.
17. Contact, grievances & data-protection contact
Our grievance / data-protection contact under the DPDP Act and GDPR is the HukProof Privacy Team, reachable at privacy@hukproof.com. For any privacy question, request, or grievance, email that address; we will acknowledge and respond within the time required by applicable law.